
Retrieve detailed information about a specific Box collaboration including participant roles, permissions, and status
Create a new collaboration to share a Box file or folder with a user or group at a specified permission level
Modify the permission level of an existing Box collaboration by changing the assigned role
Permanently remove a Box collaboration to revoke access for a user or group on a shared file or folder
Get a comment
Create a comment
Update a comment
Delete a comment
Retrieve comprehensive metadata and details for a specific file in Box including name, size, owner, timestamps, and sharing permissions
Download the content of a file in a supported format. For .txt, .docx, and .xlsx files, returns content as UTF-8 text. For other file types, returns content as a base64-encoded string to preserve binary data integrity. Inline content is capped at 1 MB; set returndownloadurl=true for a short-lived download URL instead, which handles larger files.
Upload a new file to a Box folder. Provide the bytes as base64 in content, or a filereference from the file upload API (POST /api/v1/files/) for large files, which stream into Box without entering the model's context. A staged file must be 50 MB or smaller. Use listfolder_items to find folder IDs, or '0' for the root folder. Box rejects a name already used in the folder.
Update metadata and properties of an existing file in Box including name, description, and parent folder location
Permanently delete a file from Box or move it to trash depending on configuration, removing it from all folders and collaborations
Create a duplicate copy of a file in a specified destination folder with optional rename, preserving original file content and metadata
Retrieve comprehensive metadata and details for a specific folder in Box including name, item count, owner, timestamps, and sharing permissions
List all files and subfolders contained within a Box folder with pagination, sorting, and filtering support
Create a new subfolder within a specified parent folder in Box with a unique name and optional metadata
Update metadata and properties of an existing folder in Box including name, description, and parent location for reorganization
Delete a folder from Box either recursively with all contents or as empty folder, moving to trash or permanent deletion
Create a duplicate copy of a folder and all its contents recursively to a specified destination folder with optional rename
List groups
Get group information
Create a group
Update group information
Delete a group
Search for content in Box
Get task information
Create a task
Update a task
Delete a task
Retrieve comprehensive profile information for the currently authenticated Box user including account details, storage usage, and role
Retrieve comprehensive profile information for a specific Box user by ID including account details, storage usage, and role assignments
Retrieve a paginated list of all enterprise users in Box with filtering by name, email, or user type
Create a new enterprise user account in Box with specified name, email, and access permissions
Update profile information and settings for an existing Box enterprise user including name, role, and account status
Permanently remove a Box enterprise user account and optionally transfer their content to another user
Validate Box credentials. Verifies credentials during setup.

In an mcp.json file, add the configuration below, and restart Cursor.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "url": "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
5 "headers": {
6 "Authorization": "Bearer yMt*****"
7 }
8 }
9 }
10}
11Open your Claude Desktop configuration file and add the server configuration below. You'll also need to restart the application for the changes to take effect.
Make sure Claude is using the Node v20+.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "command": "npx",
5 "args": [
6 "-y",
7 "mcp-remote@latest",
8 "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
9 "--header",
10 "Authorization: Bearer ${AUTH_TOKEN}"
11 ],
12 "env": {
13 "AUTH_TOKEN": "yMt*****"
14 }
15 }
16 }
17}Open your Windsurf MCP configuration file and add the server configuration below.
Click on the refresh button in the top right of the Manage MCP server page or in the top right of the chat box in the box icon.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "command": "npx",
5 "args": [
6 "-y",
7 "mcp-remote@latest",
8 "https://ah-api.merge.dev/api/v1/tool-packs/<tool-pack-id>/registered-users/<registered-user-id>/mcp",
9 "--header",
10 "Authorization: Bearer ${AUTH_TOKEN}"
11 ],
12 "env": {
13 "AUTH_TOKEN": "<ah-production-access-key>"
14 }
15 }
16 }
17 }In Command Palette (Cmd+Shift+P on macOS, Ctrl+Shift+P on Windows), run "MCP: Open User Configuration".
You can then add the configuration below and press "start" right under servers. Enter the auth token when prompted.
Learn more in the official documentation ↗
1{
2 "inputs": [
3 {
4 "type": "promptString",
5 "id": "agent-handler-auth",
6 "description": "Agent Handler AUTH_TOKEN", // "yMt*****" when prompt
7 "password": true
8 }
9 ],
10 "servers": {
11 "agent-handler": {
12 "type": "stdio",
13 "command": "npx",
14 "args": [
15 "-y",
16 "mcp-remote@latest",
17 "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
18 "--header",
19 "Authorization: Bearer ${input:agent-handler-auth}"
20 ]
21 }
22 }
23}It’s an MCP server that exposes data and functionality from a specific Box instance via tools. Your agents can invoke these tools to perform a wide range of actions in Box, such as creating new folders and retrieving specific files.
Here are just a few use cases:
Here are just a few popular tools across data types:
Folders
Files
Tasks
With Merge Agent Handler’s Box MCP server, you’ll also get robust platform-level capabilities for building agents:
Yes, Merge Agent Handler allows you to define custom security and data loss prevention rules that apply to all tool calls, including Box. These rules can block, redact, or mask sensitive data in tool inputs or responses based on conditions you configure.
Here are a few examples:
You can follow these steps:
1. Create an Agent Handler account. Sign in to Merge Agent Handler and grab your API key from the dashboard.
2. Create a Tool Pack. Create a Tool Pack for the workflow you want (for example, “Box + Salesforce workflows”).
3. Add the Box connector. In that Tool Pack, add Box from the connector list.
4. Authenticate Box. Choose individual auth (each end user authenticates) or shared auth (one org-level connection).
5. Complete the Box authentication flow. You’ll need to create a Registered User to represent the identity that will execute tool calls.
6. Connect your agent to the MCP entry URL. You can copy the MCP entry URL for the Tool Pack + Registered User, and add it to your agent’s MCP client config.
7. Test in the Playground. Use the Playground to run Box tool calls end-to-end before going live.
8. Set security rules (recommended). Enable default rules and add custom DLP/security rules to block, redact, or mask sensitive data in Box tool inputs/outputs.
Whether you're an engineer experimenting with agents or a product manager looking to add tools, you can get started for free now